Back to skill

Security audit

Trading Tool Free

Security checks across malware telemetry and agentic risk

Overview

This trading-analysis skill is not malicious, but it asks for broad execution/write authority and includes generic triggers and callback/export language beyond its stated single-symbol finance purpose.

Review this skill before installing. It appears to be a finance analysis prompt rather than malware, but you should only use it for trading-analysis requests, avoid supplying callback URLs unless you trust the destination, and be cautious granting write/exec access because the artifact does not include a concrete script or tight operational boundaries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a narrow single-symbol Vegas Channel analysis tool, but the interface and documentation introduce broader operational semantics such as generic create/query/export actions and arbitrary callback URLs. This ambiguity expands what an agent may believe the skill is authorized to do, increasing the risk of unintended file writes, data exfiltration, or SSRF-style outbound requests if callback handling is implemented or inferred elsewhere.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation text is overly broad and includes generic data analysis, report generation, statistics, and visualization use cases well beyond trading analysis. In agentic environments, this can cause the skill to be invoked for unrelated tasks, unnecessarily granting exec/write-capable tooling in contexts where a narrower skill should not run.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The capability coverage section enumerates an extremely broad keyword list, including fragmented and generic phrases, which creates an expansive trigger surface. In a skill-routing system this can result in accidental or adversarial invocation, exposing exec/write-enabled functionality in situations unrelated to the intended financial analysis use case.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.